Thanks for looking at my problem.
Here is the DDS.txt.
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 12:01:52.96 on 23/07/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Professional 6.1.7600.0.1252.44.1033.18.1790.867 [GMT 1:00]
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
svchost.exe 4
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
svchost.exe 4
============== Pseudo HJT Report ===============
uStart Page = www.google.com
uDefault_Page_URL = hxxp://www.stonecomputers.co.uk
BHO: txthlpBHO Class: {060235dc-6d84-47bd-95d7-a4ef5099a59d} - c:\progra~1\texthe~1\readan~1\TE4470~1.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: ba3HelperObj Class: {a17b153f-2267-4161-a165-73dcd6c31bef} - c:\progra~1\texthe~1\readan~1\BA3BHO.DLL
BHO: Javaβ’ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [HWSetup] "c:\program files\toshiba\utilities\HWSetup.exe" hwSetUP
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NIHomeAM] "c:\program files\netintelligence home\LiteClientAM.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRunOnce: [MessengerPlusLiveUninstall] "c:\users\admini~1\appdata\local\temp\MsgPlusUninstall.exe" /Cleanup
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
LSP: c:\windows\system32\NIHLSP.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
================= FIREFOX ===================
FF - ProfilePath - c:\users\admini~1\appdata\roaming\mozilla\firefox\profiles\c0zif4as.default\
FF - prefs.js: browser.search.selectedEngine - eBay.co.uk
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
β- FIREFOX POLICIES β-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnβmgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnβmgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnβp1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnβmgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
3 pxrts;pxrts
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? hwusbfake;Huawei DataCard USB Fake
R? MSSQLServerADHelper100;SQL Active Directory Helper Service
R? RsFx0103;RsFx0103 Driver
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? RtsUIR;Realtek IR Driver
R? SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS)
R? StorSvc;Storage Service
R? WatAdminSvc;Windows Activation Technologies Service
S? AMD External Events Utility;AMD External Events Utility
S? cfWiMAXService;ConfigFree WiMAX Service
S? ConfigFree Service;ConfigFree Service
S? epfwwfpr;epfwwfpr
S? MpFilter;Microsoft Malware Protection Driver
S? MpNWMon;Microsoft Malware Protection Network Driver
S? NILiteClient;Netintelligence Home Edition Client
S? pxkbf;pxkbf
S? pxscan;pxscan
S? pxsec;pxsec
S? RTL8167;Realtek 8167 NT Driver
S? rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? ServiceMonitor;Service Monitor
S? TeamViewer5;TeamViewer 5
S? TMachInfo;TMachInfo
S? vwififlt;Virtual WiFi Filter Driver
S? WTGService;WTGService
=============== Created Last 30 ================
2010-07-23 09:35:58 0 dββw- c:\program files\CCleaner
2010-07-22 22:41:18 68120 β-a-w- c:\windows\system32\PxSecure.dll-2710314
2010-07-22 22:40:46 53 β-a-w- c:\windows\wininit.ini
2010-07-21 18:29:07 0 dββw- c:\users\admini~1\appdata\roaming\Malwarebytes
2010-07-21 18:28:01 38224 β-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-21 18:27:50 0 dββw- c:\programdata\Malwarebytes
2010-07-21 18:27:48 20952 β-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-21 18:27:46 0 dββw- c:\program files\Malwarebytes' Anti-Malware
2010-07-21 18:09:19 0 d-shβw- c:\windows\ftpcache
2010-07-21 17:35:12 0 dββw- c:\users\admini~1\appdata\roaming\SUPERAntiSpyware.com
2010-07-21 17:35:12 0 dββw- c:\programdata\SUPERAntiSpyware.com
2010-07-21 17:35:00 0 dββw- c:\program files\SUPERAntiSpyware
2010-07-21 17:26:34 2396859 β-a-w- C:\MGtools.exe
2010-07-21 09:14:08 0 dββw- c:\programdata\ESET
2010-07-19 11:02:02 47 β-a-w- c:\windows\NeroDigital.ini
2010-07-18 19:11:29 0 dββw- c:\users\admini~1\appdata\roaming\InternetEverywhere
2010-07-18 13:17:39 0 dββw- c:\windows\system32\Temp
2010-07-18 11:30:44 0 dββw- c:\program files\PFConfig
2010-07-18 11:08:49 0 dββw- c:\program files\TeamViewer
2010-07-16 14:17:26 0 dββw- c:\program files\Messenger Plus! Live
2010-07-11 13:12:31 0 dββw- c:\users\admini~1\appdata\roaming\Texthelp Systems
2010-07-10 10:32:07 0 dββw- c:\users\admini~1\appdata\roaming\HTNetMeter
2010-07-10 10:32:00 0 dββw- c:\program files\HooTech
2010-07-10 10:22:21 0 dββw- c:\users\admini~1\appdata\roaming\uTorrent
2010-07-10 10:14:57 0 dββw- c:\program files\QS
2010-07-10 10:14:54 0 dββw- c:\users\admini~1\appdata\roaming\TeamViewer
2010-07-10 10:14:47 0 dββw- c:\users\administrator\temp
2010-07-10 10:08:25 0 dββw- c:\users\admini~1\appdata\roaming\NetMeter
2010-07-10 10:08:18 0 dββw- c:\program files\NetMeter
2010-07-09 15:35:15 0 β-a-w- c:\users\administrator\jagex__preferences3.dat
2010-07-09 15:35:14 99 β-a-w- c:\users\administrator\jagex_runescape_preferences2.dat
2010-07-09 15:34:49 46 β-a-w- c:\users\administrator\jagex_runescape_preferences.dat
2010-07-08 16:50:33 6576 ββw- C:\bootsqm.dat
2010-07-06 16:11:25 0 dββw- c:\users\administrator\Tracing
2010-06-26 11:41:32 5504 ββw- c:\windows\system32\drivers\imagedrv.sys
2010-06-26 11:41:32 125184 ββw- c:\windows\system32\drivers\imagesrv.sys
2010-06-26 11:41:12 106496 β-a-w- c:\windows\system32\TwnLib20.dll
2010-06-26 11:41:11 476320 ββw- c:\windows\system32\ImagXpr7.dll
2010-06-26 11:41:11 471040 ββw- c:\windows\system32\ImagXRA7.dll
2010-06-26 11:41:11 262144 ββw- c:\windows\system32\ImagXR7.dll
2010-06-26 11:41:11 1568768 ββw- c:\windows\system32\ImagX7.dll
2010-06-26 11:41:11 155648 β-a-w- c:\windows\system32\NeroCheck.exe
2010-06-26 11:33:03 0 dββw- c:\program files\uTorrent
2010-06-24 20:28:39 99176 β-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 20:28:39 297808 β-a-w- c:\windows\system32\mscoree.dll
2010-06-24 20:28:39 295264 β-a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 20:28:38 49472 β-a-w- c:\windows\system32\netfxperf.dll
2010-06-24 20:28:38 1130824 β-a-w- c:\windows\system32\dfshim.dll
2010-06-24 05:48:48 1286456 β-a-w- c:\windows\system32\ntdll.dll
2010-06-24 05:48:47 641536 β-a-w- c:\windows\system32\CPFilters.dll
2010-06-24 05:48:46 417792 β-a-w- c:\windows\system32\msdri.dll
2010-06-24 05:48:45 204288 β-a-w- c:\windows\system32\MSNP.ax
2010-06-24 05:48:45 199680 β-a-w- c:\windows\system32\mpg2splt.ax
==================== Find3M ====================
2010-06-10 18:42:49 0 βha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-06-01 17:37:48 221568 ββw- c:\windows\system32\MpSigStub.exe
2010-05-27 07:24:13 34304 β-a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49:37 293888 β-a-w- c:\windows\system32\atmfd.dll
2010-05-21 05:18:06 977920 β-a-w- c:\windows\system32\wininet.dll
2010-05-01 14:49:25 2326528 β-a-w- c:\windows\system32\win32k.sys
2010-04-27 13:45:56 72856 β-a-w- c:\windows\system32\xliveinstallhost.exe
2010-04-27 13:45:56 187544 β-a-w- c:\windows\system32\xliveinstall.dll
2009-07-14 04:56:42 31548 β-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 β-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 β-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 β-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 βsha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 β-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 β-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 β-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 β-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 βsha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 βsha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 12:05:16.98 ===============
Here is the GMER log.
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-07-23 12:31:26
Windows 6.1.7600
Running: 4y0kpw4m.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\fgrdapog.sys
β- System - GMER 1.0.15 β-
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2BAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E13634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E13898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2BF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2C1A8
β- Kernel code sections - GMER 1.0.15 β-
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A44599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A68F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, β¦] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8DC19000, 0x2D5378, 0xE8000020]
.text peauth.sys 9715BC9D 28 Bytes [5E, F6, F5, E3, 86, 19, DC, β¦]
.text peauth.sys 9715BCC1 28 Bytes [5E, F6, F5, E3, 86, 19, DC, β¦]
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 9D0BF000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, β¦]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 9D0BF123 629 Bytes [A5, 0B, 9D, FE, 05, 34, A5, β¦]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 9D0BF399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, β¦]
PAGE spsys.sys!?SPRevision@@3PADA + 538F 9D0BF3FF 136 Bytes [18, 5D, C2, 14, 00, 8B, FF, β¦]
PAGE spsys.sys!?SPRevision@@3PADA + 5418 9D0BF488 11 Bytes [89, 15, 3C, A5, 0B, 9D, E9, β¦] {MOV [0x9d0ba53c], EDX; JMP 0x240bb}
PAGE β¦
β- User code sections - GMER 1.0.15 β-
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!CreateWindowExW 75500E51 5 Bytes JMP 6F7F8157 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxIndirectParamW 75524AA7 5 Bytes JMP 6F91F5E8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxParamW 7552564A 5 Bytes JMP 6F714BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxParamA 7553CF6A 5 Bytes JMP 6F91F585 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxIndirectParamA 7553D29C 5 Bytes JMP 6F91F64B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxIndirectA 7554E8C9 5 Bytes JMP 6F91F51A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxIndirectW 7554E9C3 5 Bytes JMP 6F91F4AF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxExA 7554EA29 5 Bytes JMP 6F91F44D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxExW 7554EA4D 5 Bytes JMP 6F91F3EB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3396] ntdll.dll!LdrLoadDll 770FF625 5 Bytes JMP 011713F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!UnhookWindowsHookEx 754FCC7B 5 Bytes JMP 6F80835E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!CallNextHookEx 754FCC8F 5 Bytes JMP 6F7E9D5C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!CreateWindowExW 75500E51 5 Bytes JMP 6F7F8157 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!SetWindowsHookExW 7550210A 5 Bytes JMP 6F7A4633 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxIndirectParamW 75524AA7 5 Bytes JMP 6F91F5E8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxParamW 7552564A 5 Bytes JMP 6F714BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxParamA 7553CF6A 5 Bytes JMP 6F91F585 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxIndirectParamA 7553D29C 5 Bytes JMP 6F91F64B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxIndirectA 7554E8C9 5 Bytes JMP 6F91F51A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxIndirectW 7554E9C3 5 Bytes JMP 6F91F4AF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxExA 7554EA29 5 Bytes JMP 6F91F44D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxExW 7554EA4D 5 Bytes JMP 6F91F3EB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] ole32.dll!OleLoadFromStream 76C75B88 5 Bytes JMP 6F91F946 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] ole32.dll!CoCreateInstance 76CC57FC 5 Bytes JMP 6F7F8C45 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
β- Devices - GMER 1.0.15 β-
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
β- Registry - GMER 1.0.15 β-
Reg HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlId 136
Reg HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlModified 4
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@CrawlType 2
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@InProgress 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@DoneAddingCrawlSeeds 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@IsCatalogLevel 0
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@LogStartAddId 7
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6@CrawlNumberInProgress 137
β- EOF - GMER 1.0.15 β-
Here is the log of MBRCheck.
MBRCheck, version 1.1.1
Β© 2010, AD
\\.\C: β> \\.\PhysicalDrive0
\\.\D: β> \\.\PhysicalDrive0
Size Device Name MBR Status
βββββββββββββββ
149 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done! Press ENTER to exitβ¦
The attach.txt is here.
πAttach.txt